Official Bank 0/205

Splunk Enterprise Certified Architect Exam (SPLK-2002) - Splunk Exam Questions

Last updated on June 20, 2026

97% Exam Compliance
205 Total Questions
1
Question
In an indexer cluster, what tasks does the cluster manager perform? (select all that apply)
Select 4
Options
A Generates and maintains the list of primary searchable buckets.
B Ensures all peer nodes are always using the same version of Splunk.
C Distributes app bundles to peer nodes.
D If Indexer Discovery is enabled, provides the list of available peer nodes to forwarders.
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

2
Question
A Splunk instance has crashed, but no crash log was generated. There is an attempt to determine what user activity caused the crash by running the following search:

Exhibit

What does searching for closed_txn=0 do in this search?
Options
A Filters results to situations where Splunk was stopped and then immediately restarted.
B Filters results to situations where Splunk was started and stopped multiple times.
C Filters results to situations where Splunk was started, but not stopped.
D Filters results to situations where Splunk was started and stopped once.
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

3
Question
Which index-time props.conf attributes impact indexing performance? (Select all that apply.)
Select 4
Options
A REPORT
B ANNOTATE_PUNCT
C SHOULD_LINEMERGE
D LINE_BREAKER
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

4
Question
Which of the following Splunk deployments has the recommended minimum components for a high- availability search head cluster?
Options
A 1 search head, 1 deployer, 3 indexers
B 2 search heads, 1 deployer, 2 indexers
C 2 search heads, 1 deployer, 3 indexers
D 3 search heads, 1 deployer, 3 indexers
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

5
Question
A multi-site indexer cluster can be configured using which of the following? (Select all that apply.)
Select 4
Options
A Via Splunk Web.
B Run a Splunk edit cluster-config command from the CLI.
C Directly edit SPLUNK_HOME/etc/system/default/server.conf
D Directly edit SPLUNK_HOME/etc./system/local/server.conf
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

Finish Practice?

Are you sure you want to finish? This will end your practice session.